Score the security and context-cost of your MCP servers.
One audit, an explainable MCP Score /100 and the fixes. Paste a URL — no account needed.
or browse the 234 servers already audited — 71 rated F, listed anyway.
of context eaten by schema bloat — the #1 pain of 2026, that nobody scores + fixes.
security · tool design · schemas · reliability · context-cost · compliance · coverage.
tool poisoning, rug-pull, lethal-trifecta, exfiltration — detected and explained.
Auditing flags the risk. The gateway stops it reaching your agent.
A score is a snapshot — production needs more. Catch runtime tool-poisoning, watch for rug-pulls, and gate every MCP call in real time. Hosted, or self-hosted in your own VPC.
Behavioral evals
We actually invoke read-only tools with canary inputs and inspect the responses for tool-output prompt-injection, exfiltration and secret leakage — what static analysis can’t see.
Continuous monitoring
Tracked servers are re-checked and behaviorally re-evaluated on drift. Tool-pinning catches rug-pulls; you get drift & score-threshold alerts via webhook.
Runtime proxy
The mcpizy proxy sits on one hop between your agent and every MCP server — it caches idempotent reads (cheaper) and blocks tool-poisoning, exfiltration and secret leaks in real time (safer). One-command install.
Audited servers
| 01 | exa-search-server mcp.exa.ai | ~616 tok | 89B |
| 02 | Microsoft Learn MCP Server learn.microsoft.com | ~1.3k tok | 88B |
| 03 | huggingface.co/mcp huggingface.co | ~5.0k tok | 87B |
| 04 | Context7 mcp.context7.com | ~1.2k tok | 87B |
| 05 | docs-ai-search docs.mcp.cloudflare.com | ~469 tok | 86B |
| 06 | GitMCP gitmcp.io | ~544 tok | 83B |
Browse by category
all collections ›Independently-audited rankings of the best and safest MCP servers by use case — and head-to-head comparisons.
How the MCP Score is computed
Six weighted pillars (reliability shown but not yet credited), hard floors (secret-in-schema → cap D, failed handshake → cap F), and a traceable attribution for every penalty.
- Security/20
- Tool design/18
- Schemas / desc/16
- Reliability/14
- Context-cost/12
- Compliance/12
- Coverage/8
Calibrated on the real MCP ecosystem · official spec 2025-11-25 · annotations, OAuth 2.1/PKCE, cursor pagination, JSON-RPC errors.
MCP security & auditing — FAQ
Common questions about checking, scoring and protecting Model Context Protocol servers.